ShinyHunters Hijacked Dark Web Site of Cybercrime Group cl0p

The rival group seized cl0p infrastructure after discovering a software vulnerability, escalating a dispute over a stolen exploit.

Updated on Sept. 21, 2026 in Cybersecurity

ShinyHunters Hijacked Dark Web Site of Cybercrime Group cl0p

Live Poll

Do you trust that law enforcement can effectively stop large-scale cybercrime rings?

The cybercrime collective ShinyHunters claimed control of the dark web site belonging to rival gang cl0p after identifying a software vulnerability. The site displayed a seizure notice on Saturday before becoming completely unreachable by Sunday.

Why it matters

This incident highlights a escalating conflict between major cybercrime syndicates over the ownership of software exploits used in high-volume data theft. The feud centers on allegations that cl0p misappropriated a vulnerability from ShinyHunters last year.

ShinyHunters gained control over cl0p infrastructure by exploiting an unnamed software vulnerability. This follows cl0p's historically broad targeting, which utilized a MOVEit file transfer bug to compromise data across 600 companies in 2023.

The players

ShinyHunters

A cybercrime group known for data exfiltration and maintaining a presence on the dark web.

cl0p

A prolific cybercrime gang notorious for large-scale data theft via software vulnerabilities.

The details

ShinyHunters allegedly utilized a specific software vulnerability discovered on Friday to gain administrative access to cl0p's dark web infrastructure. This methodology mirrors the tactics used by ransomware groups that leverage vulnerabilities in common enterprise software to gain network access. By exploiting these weaknesses, the groups bypass standard authentication protocols to secure unauthorized control over server operations.

Timeline

  1. 2023: cl0p exploited a MOVEit software bug to breach hundreds of companies.

  2. September 18, 2026: ShinyHunters reportedly identified a vulnerability in cl0p software.

  3. September 19, 2026: The cl0p dark web site displayed a message claiming the domain was seized by ShinyHunters.

  4. September 20, 2026: The cl0p dark web site became unreachable.

The Tech Race

This development follows a pattern of infrastructure disruption established by the 2023 cl0p MOVEit software vulnerability exploitation, which demonstrated the severe impact of systemic software flaws on global corporate data security. The conflict reflects an escalating competitive dynamic where rival groups target each other's technical capabilities to gain an advantage in the cybercrime ecosystem.

Organizations that rely on secure file transfer systems should monitor for evidence of any new vulnerabilities being exploited in the wake of this internal gang conflict. There is currently no evidence that this specific incident has shifted the security risk for end-users, though systemic exploits remain a persistent threat to corporate networks.

The takeaway

The infighting between these groups illustrates the volatile nature of the dark web exploit economy. Security researchers and IT departments should watch for any technical indicators of compromise shared or released by ShinyHunters as they potentially leak information gathered from cl0p.

Further reading

For more on the current threat landscape, see Cybersecurity.

Live Poll

Do you trust that law enforcement can effectively stop large-scale cybercrime rings?

ShinyHunters Hijacked Dark Web Site of Cybercrime Group cl0p